Description
Use after free in UI in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free error located in the user interface of Google Chrome. The flaw can be triggered by a specially crafted HTML page that causes a memory pointer to be accessed after the memory has been freed. When this occurs, a remote attacker may be able to escape Chrome’s sandbox, potentially executing arbitrary code outside the browser process. The weaknesses are identified as CWE‑416 and CWE‑825, highlighting memory safety issues that can lead to privilege escalation and integrity compromise.

Affected Systems

All users running Google Chrome versions prior to 148.0.7778.216 are affected. The issue applies to all platforms where the Chrome browser includes the vulnerable UI component. Versions newer than 148.0.7778.216 are not impacted as the patch has been applied.

Risk and Exploitability

The vulnerability has a CVSS score of 8.3, indicating high severity, and is listed as a use‑after‑free that can lead to sandbox escape. The EPSS score is < 1%, and the vulnerability is not currently listed in the CISA KEV catalog, suggesting that documented public exploitation is not yet confirmed. However, the nature of the flaw—remote exploitation via a crafted HTML page—may allow an attacker to design an exploit that could be delivered through a malicious website or email attachment. Given this possibility, the risk remains significant until the software is updated to the fixed version. The likely attack vector is an attacker‑controlled web page that the victim opens in Chrome, allowing the exploit to be delivered without additional credentials.

Generated by OpenCVE AI on May 29, 2026 at 16:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 148.0.7778.216 or newer
  • If a timely update is unavailable, consider blocking or removing access to potentially malicious HTML content to mitigate exposure
  • Enable Chrome’s safe browsing and enforce web content filtering to prevent delivery of malicious HTML pages

Generated by OpenCVE AI on May 29, 2026 at 16:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 29 May 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome UI Enabling Sandbox Escape via Crafted HTML chromium-browser: Use after free in UI
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}

threat_severity

Important


Fri, 29 May 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 29 May 2026 00:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome UI Enabling Sandbox Escape via Crafted HTML

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Use after free in UI in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T14:38:53.636Z

Reserved: 2026-05-28T17:24:58.589Z

Link: CVE-2026-9951

cve-icon Vulnrichment

Updated: 2026-05-29T14:38:50.241Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-28T23:16:53.250

Modified: 2026-05-29T16:28:02.983

Link: CVE-2026-9951

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-9951 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T15:45:16Z

Weaknesses